GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
124 advisories
Filter by severity
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component:...
Low
Unreviewed
CVE-2026-60936
was published
Jul 22, 2026
Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component:...
Low
Unreviewed
CVE-2026-61048
was published
Jul 22, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component:...
Low
Unreviewed
CVE-2026-47022
was published
Jul 22, 2026
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component:...
Low
Unreviewed
CVE-2026-62508
was published
Jul 22, 2026
Keystone: GraphQL API Endpoint Lacks Query Depth Limits
Low
CVE-2026-10802
was published
for
@keystone-6/core
(npm)
Jun 4, 2026
Code Index MCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10692
was published
for
code-index-mcp
(pip)
Jun 3, 2026
DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10691
was published
for
@wonderwhy-er/desktop-commander
(npm)
Jun 3, 2026
A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram...
Low
Unreviewed
CVE-2026-14684
was published
Jul 5, 2026
A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function...
Low
Unreviewed
CVE-2026-14683
was published
Jul 5, 2026
Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
Low
CVE-2026-44242
was published
for
io.micronaut:micronaut-inject
(Maven)
May 6, 2026
A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This...
Low
Unreviewed
CVE-2026-11478
was published
Jun 8, 2026
Vantage6: No limit on emails sent for password/MFA reset
Low
CVE-2024-24769
was published
for
vantage6
(pip)
Jun 5, 2026
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of...
Low
Unreviewed
CVE-2026-10705
was published
Jun 3, 2026
A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info...
Low
Unreviewed
CVE-2026-10156
was published
May 31, 2026
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
Low
CVE-2026-8769
was published
for
@ai-sdk/provider-utils
(npm)
May 18, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
CVE-2026-45756
was published
for
symfony/json-path
(Composer)
May 28, 2026
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function...
Low
Unreviewed
CVE-2026-8124
was published
May 8, 2026
OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
Low
CVE-2026-41913
was published
for
openclaw
(npm)
Apr 9, 2026
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of...
Low
Unreviewed
CVE-2026-31051
was published
Apr 24, 2026
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability...
Low
Unreviewed
CVE-2026-0992
was published
Jan 15, 2026
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
Low
Unreviewed
CVE-2026-6416
was published
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API